Mailing List Archive

Clam AntiVirus UUencoded Message Denial of Service Vulnerability
Those using ClamAV should check out this advisory:

<http://www.secunia.com/advisories/10826/>
Re: Clam AntiVirus UUencoded Message Denial of Service Vulnerability [ In reply to ]
On Tuesday 10 February 2004 16:38, Kenneth Porter wrote:
> Those using ClamAV should check out this advisory:
>
> <http://www.secunia.com/advisories/10826/>


thanks for that info. I hope there is a fix soon.
--
-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-
Brook Humphrey
Mobile PC Medic, 420 1st, Cheney, WA 99004, 509-235-9107
http://www.webmedic.net, bah@webmedic.net, bah@linux-mandrake.com
Holiness unto the Lord
-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-~`'~-
Re: Clam AntiVirus UUencoded Message Denial of Service Vulnerability [ In reply to ]
On Tue, Feb 10, 2004 at 05:06:30PM -0800, Brook Humphrey said:
> On Tuesday 10 February 2004 16:38, Kenneth Porter wrote:
> > Those using ClamAV should check out this advisory:
> >
> > <http://www.secunia.com/advisories/10826/>
>
>
> thanks for that info. I hope there is a fix soon.

The fix has been in CVS since a few hours after 0.65 was released. 0.66
is due to release shortly (it may have already, but I haven't looked
back for a few hours).

--
--------------------------------------------------------------------------
| Stephen Gran | Be careful how you get yourself |
| steve@lobefin.net | involved with persons or situations |
| http://www.lobefin.net/~steve | that can't bear inspection. |
--------------------------------------------------------------------------
Re: Clam AntiVirus UUencoded Message Denial of Service Vulnerability [ In reply to ]
--On Tuesday, February 10, 2004 8:09 PM -0500 Stephen Gran
<steve@lobefin.net> wrote:

> The fix has been in CVS since a few hours after 0.65 was released. 0.66
> is due to release shortly (it may have already, but I haven't looked
> back for a few hours).

The DB mirror is no longer specified in a text file but with an
undocumented directive in the clamav.conf file. (It might be in the PDF; I
didn't see it in any of the man pages.)

# undocumented in 0.66, gleaned from freshclam source
DatabaseMirror database.clamav.net
Re: Clam AntiVirus UUencoded Message Denial of Service Vulnerability [ In reply to ]
On Tue, 10 Feb 2004, Kenneth Porter wrote:

> --On Tuesday, February 10, 2004 8:09 PM -0500 Stephen Gran
> <steve@lobefin.net> wrote:
>
> > The fix has been in CVS since a few hours after 0.65 was released. 0.66
> > is due to release shortly (it may have already, but I haven't looked
> > back for a few hours).
>
> The DB mirror is no longer specified in a text file but with an
> undocumented directive in the clamav.conf file. (It might be in the PDF; I
> didn't see it in any of the man pages.)
>
> # undocumented in 0.66, gleaned from freshclam source
> DatabaseMirror database.clamav.net

A fresh install should also install a new config
file .../etc/freshclam.conf that contains that config line.

If freshclam finds that file, it will use it, else it looks for
those directives in the clamav.conf file.

--
Dave Funk University of Iowa
<dbfunk (at) engineering.uiowa.edu> College of Engineering
319/335-5751 FAX: 319/384-0549 1256 Seamans Center
Sys_admin/Postmaster/cell_admin Iowa City, IA 52242-1527
#include <std_disclaimer.h>
Better is not better, 'standard' is better. B{
Re: Clam AntiVirus UUencoded Message Denial of Service Vulnerability [ In reply to ]
--On Wednesday, February 11, 2004 12:59 AM -0600 David B Funk
<dbfunk@engineering.uiowa.edu> wrote:

> A fresh install should also install a new config
> file .../etc/freshclam.conf that contains that config line.
>
> If freshclam finds that file, it will use it, else it looks for
> those directives in the clamav.conf file.

Ah, I adapted an SRPM for 0.65, so it didn't know about the new file. I'll
have to check with the packager to see if he's updated his RPM.